Continuous improvements to national cybersecurity policies are necessary due to the rapidly evolving cyber threat landscape, growing reliance on information and communication technologies (ICTs), and the prevalence of digital dangers. The process of evaluating cybersecurity maturity is becoming more and more crucial in the dynamic digital environment. Governments can do a thorough assessment of a nation's cybersecurity capabilities by using a cybersecurity maturity model. This allows them to pinpoint areas of weakness and offer specific recommendations for strengthening cybersecurity capabilities. These assessments serve as a standard for illustrating a country's readiness for cyberattacks (where cyber readiness refers to the organisation’s ability to identify, prevent and respond to cyber threats). However, the results of these maturity assessment models are not sufficient for creating national cyber security policies since they are overly generalised and deficient in the evaluation of present capabilities. The focus of this study is to propose a model that takes into consideration multiple factors having greater relevance to national cyber security strategies. This model introduces a profiling approach that carefully evaluates the country's readiness based on the current state of the cyber security initiatives taken at the national level. The key areas considered in the evaluation include threat landscape, overall cyber security posture, initiatives, legal frameworks, infrastructure support, collaborations, capacity, and workforce-building initiatives. To find the utilisation of the novel profiling approach, we have applied it to four selected countries that are recognised as potential targets for threats due to their growing internet population and connectivity. Our research outcome reveals that the profiling techniques reflect the current state of readiness at the national and organisational level to a greater extent and are more optimised for cyber maturity assessment.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Profile-Based Cyber Security Readiness Assessment Framework at Country Level

  • Raymond Agyemang,
  • Steven Furnell,
  • Tim Muller

摘要

Continuous improvements to national cybersecurity policies are necessary due to the rapidly evolving cyber threat landscape, growing reliance on information and communication technologies (ICTs), and the prevalence of digital dangers. The process of evaluating cybersecurity maturity is becoming more and more crucial in the dynamic digital environment. Governments can do a thorough assessment of a nation's cybersecurity capabilities by using a cybersecurity maturity model. This allows them to pinpoint areas of weakness and offer specific recommendations for strengthening cybersecurity capabilities. These assessments serve as a standard for illustrating a country's readiness for cyberattacks (where cyber readiness refers to the organisation’s ability to identify, prevent and respond to cyber threats). However, the results of these maturity assessment models are not sufficient for creating national cyber security policies since they are overly generalised and deficient in the evaluation of present capabilities. The focus of this study is to propose a model that takes into consideration multiple factors having greater relevance to national cyber security strategies. This model introduces a profiling approach that carefully evaluates the country's readiness based on the current state of the cyber security initiatives taken at the national level. The key areas considered in the evaluation include threat landscape, overall cyber security posture, initiatives, legal frameworks, infrastructure support, collaborations, capacity, and workforce-building initiatives. To find the utilisation of the novel profiling approach, we have applied it to four selected countries that are recognised as potential targets for threats due to their growing internet population and connectivity. Our research outcome reveals that the profiling techniques reflect the current state of readiness at the national and organisational level to a greater extent and are more optimised for cyber maturity assessment.